CVE-2011-3053 is a use-after-free vulnerability in Google Chrome versions prior to 17.0.963.83, also affecting Apple and openSUSE products, stemming from issues with block splitting. This vulnerability carries a CVSS score of 6.8, indicating a medium severity risk where an unauthenticated remote attacker could exploit it with medium complexity to achieve partial confidentiality, integrity, and availability impacts, potentially leading to denial of service or other unspecified consequences. While there is no evidence of active exploitation in the wild (not in KEV), no public exploit code (Metasploit, Nuclei, ExploitDB), and limited community discussion, its FAUCET Risk Score of 53/100 suggests a moderate overall risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.0.963.83CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 10.7CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* | ||
< 6.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 6.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
12.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.